Workforce data, protected in the design
CrewAware holds records about people, hours, jobsites and pay preparation. Here is how the product actually protects them — stated from the engineering, not from a brochure.
Three properties the product is built around
Server-authoritative by default
The state that matters — who may sign up, what a subscription allows, whether a punch counts — is decided on the server. A clever browser cannot talk CrewAware into a different answer.
Isolated by company
Every workforce record belongs to a company, and authorization compares that ownership on the way to every record. One company's crews, hours and projects are not another company's to see.
Accountable records
Punches, breaks and corrections are recorded as individual events with history. Time entries cannot be deleted, and approved records stop being editable — the record holds.
Authenticated access, throttled at the door
Nothing operational in CrewAware is reachable without an authenticated, email-verified account inside an active company workspace.
Company boundaries enforced in code
CrewAware is multi-company software, and the boundary between companies is an authorization rule, not a convention.
Time records that hold up
The value of a time record is what it can prove later. CrewAware is built so the record survives the people arguing about it.
Location handled honestly
GPS evidence is only worth something if it is collected honestly and bounded clearly.
The marketing site holds nothing sensitive
crewaware.app — the site you are reading — is deliberately separate from the application and deliberately minimal.
Built and released carefully
Security is mostly habits. These are the ones CrewAware's engineering actually keeps.
Questions about security?
If you have a security question about CrewAware, or believe you have found a vulnerability, contact us and it will reach the engineering team.
Contact CrewAwareSecurity questions
Can another company see our data?
No. Every record in CrewAware belongs to a company, and access checks compare that ownership on the way to the record itself rather than trusting the request that asked for it. Isolation is a property of the data path, not a setting somebody has to remember to switch on.
How do we control what our own people can see?
Roles and permissions, administered inside your workspace. What a given person may open, change or approve is decided on the server for each request — a browser cannot talk CrewAware into a different answer by asking differently.
Is there an audit trail?
Yes, on the things that matter for a pay dispute. Punches, breaks, corrections and approvals are individual events, correction requests keep who asked and who approved, and time entries cannot be deleted by anyone. That is what makes the record usable as evidence rather than as a summary.
Do you have SOC 2, ISO 27001 or a pen-test report?
No, and we will not imply otherwise. CrewAware describes the controls it can actually demonstrate in the product, and nothing on this page is a certification, an attestation or an audited claim. If a formal attestation is a requirement for your business, we would rather you know that now.